Search by job, company or skills

GRC Cybersecurity Analyst

2-4 Years
  • Posted 5 hours ago
  • Be among the first 10 applicants

Job Description

About Us

HireKayana is a talent agency that connects Filipino Remote Professionals with global companies that operate within real systems and value disciplined execution. These are long-term professional roles—not gig work. Our partners build structured teams where accountability, clear communication, and operational discipline matter.

About the Role

Our partner is a US-based cybersecurity consulting firm that provides virtual CISO (vCISO) services. Its clients are typically mid-sized tech firms with real cybersecurity needs but not yet large enough for a full-time CISO. You'll work alongside a vCISO to deliver cybersecurity leadership in Governance, Risk, and Compliance (GRC) directly to clients across many industries.

This is a leadership-track GRC role, not a hands-on SOC role. It does not involve routine tasks like monitoring logs, responding to alerts, patching, or running vulnerability scans. If you have technical or SOC experience and want to move toward thoughtful cybersecurity leadership, this is a strong fit.

What You'll Do

Audits & Risk Assessments

  • Lead internal cybersecurity audits to keep clients environments compliant and secure
  • Perform quantitative risk assessments so clients can prioritize their security investments

Policy, Documentation & Compliance

  • Write cybersecurity policy documents to build up clients programs
  • Respond to security questionnaires from clients customers
  • Assist with evidence collection to prepare clients for external compliance audits

Client Advisory & Account Management

  • Advise clients across a wide range of cybersecurity topics
  • Project manage client accounts to keep them on track
  • Plan and run tabletop exercises so clients teams can practice incident response

Service Development

  • Contribute to the service development program to improve client deliverables

What We're Looking For

Non-Negotiables

  • 2+ years in a technical security role (SOC analyst, developer, incident response, technical auditor, or IT administrator with security responsibilities)
  • Strong technical writing—able to produce clear policy documents and explain concepts to a client's leadership team
  • Experience managing internal projects and initiatives; self-managing and reliable on deadlines
  • High personal and professional ethical standards
  • Growth-oriented, collaborative, and comfortable adapting across many industries and client environments

Preferred Qualifications

  • Background in compliance frameworks (SOC 2, ISO 27001, PCI-DSS, HIPAA, TX-RAMP) or security frameworks (NIST CSF, CIS, COBIT)
  • Experience in security operations, secure SDLC, system administration (Windows/Linux), cloud administration (AWS, Azure, Google Cloud), or network/firewall administration
  • Familiarity with security tools and concepts (SIEM, WAF, vulnerability scanning, penetration testing, MFA, SSO, encryption, SSL/TLS)
  • General scripting or coding experience
  • Cybersecurity certifications (SSCP, CompTIA Security+, or similar)
  • Degree in Cybersecurity or a related field

More Info

Job Type:
Industry:
Function:
Employment Type:

About Company

Job ID: 152372281

Similar Jobs

Philippines, Quezon City

Skills:

Iso 27001It OperationsDLP PoliciesZscaler for Endpointcybersecurity awareness trainingrisk assessmentsKRI developmentsecurity control evaluationsNIST CSFCompliance AuditsCIS Controlsgap analysesSOC 2third-party risk assessmentscybersecurity policiesvendor security evaluationscybersecurity governancecybersecurity best practices

Beware of Scammers

We don’t charge money for job offers